Quick Links

    Decian blog

    Threat Advisories

    CISA Advisory ICSA-26-204-06: Managing Risk in MZ Automation libIEC61850

    Jake McDowell ยท 2026-07-27

    CISA has issued advisory ICSA-26-204-06 warning of severe vulnerabilities in the MZ Automation libIEC61850 software library. This library is widely used to support the IEC 61850 standard, which governs communication for power generation, substation automation, and related critical infrastructure. The advisory identifies four distinct flaws that could allow an unauthenticated network-adjacent attacker to disrupt services or take control of a system.

    The affected versions of the library range from 1.0.0 up to 1.6.1. The risks here are not theoretical. Two of the identified flaws involve buffer overflows, specifically a stack-based overflow and a heap-based overflow. An attacker could exploit these to execute arbitrary code or cause a denial of service. Another vulnerability allows an attacker to crash a system by sending a malformed message, while a fourth flaw stems from improper handling of invalid data structures.

    For mid-market organizations operating in manufacturing, energy, or transportation, the implications are significant. These sectors rely heavily on the visibility and control functions that IEC 61850 facilitates. A crash in a protection system could lead to operational outages or safety risks. The advisory notes that remote code execution is possible, particularly in configurations where Address Space Layout Randomization (ASLR) is disabled. This means the threat is not limited to simple outages but includes the potential for deeper system compromise.

    CISA reports that no public exploitation of these specific flaws has been observed yet. However, the absence of active attacks does not eliminate the risk. The vulnerabilities allow for network-adjacent attacks, meaning an attacker does not need internet access to exploit them if they can reach the internal network segment where the device resides. This makes network segmentation and strict access controls even more critical for organizations running these components.

    The vendor, MZ Automation, has released updated builds to address these issues. Organizations must prioritize verifying their software versions against the advisory to determine if they are affected. The remediation path involves updating the library to the latest build available through the vendor's GitHub repository. Before applying updates, teams should conduct a risk assessment to understand the operational impact, as restarting affected services may be necessary.

    Here are the practical next steps for IT and security teams managing ICS assets:

    Securing industrial control systems requires vigilance and a structured approach to patch management. At Decian, our SOC and MDR services provide the continuous monitoring and expertise needed to detect threats targeting these critical assets. We help mid-market organizations and their MSP partners navigate these complexities with proactive defense strategies. Visit www.decian.com to learn how we can support your cybersecurity posture.

    ยฉ 2025 Decian, Inc. All rights reserved.